Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2972+ Articles
168+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Google Hit With $463 Million Fine for EU Location Data Rule Breach
Google Hit With $463 Million Fine for EU Location Data Rule Breach
NEWS

Google Hit With $463 Million Fine for EU Location Data Rule Breach

Ireland's DPC fined Google €403M ($463M) after finding it unlawfully processed Location History, Web & App Activity, and Location Accuracy data.

Dylan H.

News Desk

September 21, 2026
3 min read

The Fine

Google has been fined €403 million ($463 million) by Ireland's Data Protection Commission (DPC) for breaching the EU's General Data Protection Regulation (GDPR) through how it handled users' location data. The DPC announced the penalty Monday, capping an investigation that first opened six years ago.

Ireland is Google's lead EU regulator because the company's European headquarters sits in Dublin — under GDPR's "one-stop-shop" mechanism, the DPC in a company's home member state takes point on cross-border enforcement actions.


What Investigators Found

The DPC's investigation concluded Google failed to process location data lawfully, fairly, or transparently across three separate surfaces:

  • Web & App Activity — the Google account setting that logs browsing and search history
  • Location History — the service that maps the places a user's phone has physically been
  • Location Accuracy — an Android OS feature that improves positioning precision using additional signals

In each case, regulators found the legal basis and transparency around how that data was collected and processed did not meet GDPR's requirements.


Where This Ranks

At €403 million, this is the fourth-largest privacy fine the Irish DPC has ever issued. It trails the regulator's biggest actions against Meta, including a €1.2 billion fine — still the largest GDPR penalty on record. The DPC has now built a track record of issuing nine- and ten-figure fines against the largest US tech platforms operating in the EU.

Notably, this isn't Google's only open matter with the Irish regulator: the DPC says it has three additional investigations into Google still ongoing, meaning further enforcement action is possible.


Why This Matters

A six-year investigation resulting in a $463 million fine underscores how methodically EU regulators are willing to work through complex cross-border cases against the largest tech companies — and how location data specifically remains one of the most heavily scrutinized categories under GDPR, given its sensitivity and the ease with which it can be used to infer a person's habits, relationships, and daily movements. For any organization processing location signals from EU users — not just Google-scale platforms — this fine is a reminder that lawful basis and transparency obligations apply with equal weight regardless of company size, and that DPC investigations can span years before resulting in enforcement.


References

  • Google hit with $463 million fine for EU location data rule breach — AP News
#Google#GDPR#Ireland DPC#Location Data#Privacy Fine#Android

Related Articles

Google Loses Final Appeal to Overturn €4.1 Billion EU Antitrust Fine

The Court of Justice of the European Union has dismissed Google's final appeal against a €4.1 billion antitrust fine, confirming that the company...

4 min read

Spain Fines 23andMe Nearly $3 Million for Cybersecurity Failings Enabling 2023 Hack

Spain's data protection agency AEPD has fined 23andMe approximately $3 million for cybersecurity failures that enabled the 2023 credential-stuffing breach...

5 min read

Uber Fined €825 Million by Dutch Regulators Over Automated Driver Account Suspensions

The Dutch DPA fined Uber €825M for GDPR violations after its algorithm suspended driver accounts without meaningful human review or transparent explanation.

4 min read
Back to all News